nerdexam
Microsoft

SC-300 · Question #155

You have an Azure Active Directory (Azure AD) tenant that uses Azure AD Identity Protection and contains the resources shown in the following table. Azure Multi-factor Authentication (MFA) is…

The correct answer is B. Mark User1 as compromised. Scenario: User compromised (True positive) 'Risky users' report shows an at-risk user [Risk state = At risk] with low risk [Risk level = Low] and that user was indeed compromised. Feedback: Select the user and click on 'Confirm user compromised'. What happens under the hood?…

Submitted by brentm· Mar 6, 2026Implement authentication and access management

Question

You have an Azure Active Directory (Azure AD) tenant that uses Azure AD Identity Protection and contains the resources shown in the following table. Azure Multi-factor Authentication (MFA) is enabled for all users. User1 triggers a medium severity alert that requires additional investigation. You need to force User1 to reset his password the next time he signs in. The solution must minimize administrative effort. What should you do?

Exhibit

SC-300 question #155 exhibit

Options

  • AReconfigure the user risk, policy to trigger on medium or low severity.
  • BMark User1 as compromised.
  • CReset the Azure MIFA registration for User1.
  • DConfigure a sign-in risk policy.

How the community answered

(42 responses)
  • A
    5% (2)
  • B
    81% (34)
  • C
    12% (5)
  • D
    2% (1)

Explanation

Scenario: User compromised (True positive) 'Risky users' report shows an at-risk user [Risk state = At risk] with low risk [Risk level = Low] and that user was indeed compromised. Feedback: Select the user and click on 'Confirm user compromised'. What happens under the hood? Azure AD will move the user risk to High [Risk state = Confirmed compromised; Risk level = High] and will add a new detection 'Admin confirmed user compromised'. Notes: Currently, the 'Confirm user compromised' option is only available in 'Risky users' report. The detection 'Admin confirmed user compromised' is shown in the tab 'Risk detections not linked to a sign-in' in the 'Risky users' report. https://docs.microsoft.com/en-us/azure/active-directory/identity-protection/howto-identity- protection-risk-feedback

Topics

#Identity Protection#user risk#compromised account#forced password reset

Community Discussion

No community discussion yet for this question.

Full SC-300 Practice